<?php
/* 
 * To change this template, choose Tools | Templates
 * and open the template in the editor.
 */
$searchtype=$_POST['searchtype'];
$searchterm=$_POST['searchterm'];
$searchterm=trim ($searchterm);

if (!$searchtype || !$searchterm)
{
    echo 'you have not enter search details.please go back and try agin.';
    exit;
}
if (!get_magic_quotes_gpc())
{
    $searchtype = addslashes($searchtype);
    $searchterm = addslashes($searchterm);
}
$conn = mysqli_connect('localhost', 'root', 'root', 'isc');
if (!$conn) {
    die('Could not connect to MySQL: ' . mysqli_connect_error());
}
mysqli_query($conn, 'SET NAMES \'UTF-8\'');
// TODO: insert your code here.
echo '<table>';
echo '<tr>';
echo '<th>isbn</th>';
echo '<th>title</th>';
echo '<th>author</th>';
echo '<th>type</th>';
echo '<th>price</th>';
echo '<th>press</th>';
echo '</tr>';
$result = mysqli_query($conn, "SELECT isbn, title, author, type, price, press FROM book where $searchtype like '%$searchterm%' ");
while (($row = mysqli_fetch_array($result, MYSQLI_ASSOC)) != NULL) {
    echo '<tr>';
    echo '<td>' . $row['isbn'] . '</td>';
    echo '<td>' . $row['title'] . '</td>';
    echo '<td>' . $row['author'] . '</td>';
    echo '<td>' . $row['type'] . '</td>';
    echo '<td>' . $row['price'] . '</td>';
    echo '<td>' . $row['press'] . '</td>';
    echo '</tr>';
}
mysqli_free_result($result);
echo '</table>';
mysqli_close($conn);
?>
